Vulnerabilities
Vulnerable Software
Sendmail:  >> Sendmail  >> 4.55  Security Vulnerabilities
sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
CVSS Score
7.5
EPSS Score
0.01
Published
2010-01-04
Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header.
CVSS Score
5.0
EPSS Score
0.183
Published
2009-05-05


Contact Us

Shodan ® - All rights reserved